HITRUST Implementation vs. Measured PRISMA Levels: What Is the Difference?
LevelBlue Completes Acquisition of Cybereason. Learn more
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
LevelBlue Completes Acquisition of Cybereason. Learn more
In the context of the HITRUST CSF, the PRISMA Maturity Levels are designed to help organizations assess their cybersecurity posture and maturity in relation to security controls and practices. The PRISMA maturity levels are structured to reflect different stages of an organization’s ability to effectively implement and manage cybersecurity controls. Two of the PRISMA levels are Implementation and Measured. Both Implementation and Measured both involve control testing; however, they represent two different stages of control maturity with distinct characteristics.
Implementation level compliance indicates that an organization has successfully put in place the required security controls or safeguards as prescribed by HITRUST. However, at this stage, the organization’s processes and controls are primarily focused on meeting the minimum requirements and may still be in the early phases of becoming fully operational and optimized.
An organization has implemented multi-factor authentication (MFA) for all users as required by HITRUST, but the process may still be manual in nature (e.g., users are manually enrolled, and there’s no automation for prompt deactivation or enforcement). The control is implemented but may not be fully optimized or operating at a high level of maturity.
Represents the stage where the organization not only implements the controls but also actively measures, monitors, and evaluates the effectiveness of those controls. This PRISMA level demonstrates that the organization is moving beyond simply "checking the box" for control implementation and is focused on assessing the performance of its security measures over time.
An organization has implemented multi-factor authentication (MFA) for all users, but it goes beyond implementation by regularly measuring the effectiveness of MFA in preventing unauthorized access attempts. It might track metrics such as the number of login failures, monitor any MFA-related incidents, and conduct regular audits to ensure MFA usage remains optimal. Any gaps identified in the process would trigger a refinement process to make MFA more secure or user-friendly.

LevelBlue is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.